According to Slowmist, on May 19-20, attackers compromised the npm account atool and automatically published 637 malicious versions across 317 packages within 22 minutes. Between 00:19 and 00:54 Beijing time on May 20, attackers uploaded durabletask versions 1.4.1, 1.4.2, and 1.4.3, impersonating Microsoft's official releases.
Affected high-frequency components include AntV and Echarts-for-react in npm ecosystem, and durabletask in Python. Slowmist linked the GitHub token mass leak and Grafana Labs ransomware attacks to this campaign. Attackers could steal credentials, gain unauthorized access to internal repositories, move laterally through CI/CD pipelines, and extort organizations using compromised GitHub tokens.